Owner Control of Electronic Devices via Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In corporate environments, employees using electronic devices often circumvent control measures by deleting or altering policy files, leading to a lack of effective owner control over device usage, as existing methods rely on user compliance with company policies and are vulnerable to circumvention.

Innovation Solution

A system and method for owner control of electronic devices, involving an owner information store for data integrity and source authentication, and an owner control information store to restrict operations, with digitally signed erase commands ensuring secure management of owner information and control settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policy files are loaded onto devices to restrict operations, then owner control over device usage is improved, but users can circumvent control by deleting or replacing policy files

Engineering Contradiction:
Improveowner control effectivenessVSAvoiduser ability to modify device settings
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system separates policy management into two distinct components: policy files that define restrictions and digitally signed commands that authorize changes. This segmentation ensures that users cannot simply delete or replace policy files, as any modification requires a valid digitally signed command from an authorized source, thus maintaining owner control while allowing legitimate user operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system pre-loads policy files onto devices during initial setup or provisioning, before users can potentially circumvent them. These policy files are established in advance with digital signatures that verify their authenticity. Any subsequent changes to policies or device settings require pre-authenticated digitally signed commands, preventing users from arbitrarily modifying restrictions after receiving the device.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If users are allowed to make changes to device settings, then ease of operation is improved, but owner control and policy compliance deteriorate

Engineering Contradiction:
Improveuser ability to modify deviceVSAvoidpolicy compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces digitally signed commands as an intermediary mechanism between user requests and device setting changes. When a user attempts to modify device settings, the system checks for a valid digitally signed command that authorizes the specific change. This intermediary layer allows legitimate user operations to proceed while blocking unauthorized modifications, thus maintaining both ease of operation for authorized users and policy compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where any attempt to modify device settings triggers a verification process. The system checks whether a valid digitally signed command exists for the requested change and provides feedback by either allowing or blocking the modification. This feedback loop ensures that users can make necessary changes when authorized while automatically preventing policy violations, maintaining both usability and compliance.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7793355B2System and method of owner control of electronic devices
Publication Date: 2010.09.07 MALIKIE INNOVATIONS LTD
  • US7793355B2 patent drawing
  • US7793355B2 patent drawing
  • US7793355B2 patent drawing

AI summary

A system and method of owner control of an electronic device are provided. Owner identification information, such as data integrity and source authentication information, is stored on the electronic device. Received owner control information is stored on the electronic device where the integrity of the received owner control information is verified and/or the source is authenticated using the owner identification information. In one embodiment, owner identification information comprises an owner signature private key.